CVE-2014-3316: Input Validation
The Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager allows remote authenticated users to bypass intended upload restrictions via a crafted parameter, aka Bug ID CSCup76297.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3316?
CVE-2014-3316 is considered a high severity vulnerability due to its potential to allow remote authenticated users to bypass upload restrictions.
How do I fix CVE-2014-3316?
To fix CVE-2014-3316, apply the relevant Cisco patch or upgrade to a fixed version of Cisco Unified Communications Manager.
What systems are affected by CVE-2014-3316?
CVE-2014-3316 affects Cisco Unified Communications Manager, particularly versions prior to 10.0(1) base.
Who can exploit CVE-2014-3316?
Only remote authenticated users can exploit CVE-2014-3316 to bypass intended upload restrictions.
Is there a workaround for CVE-2014-3316?
There is currently no documented workaround for CVE-2014-3316, so patching is the recommended action.